Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

3978 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.31%—Angeljudesuarez Online Voting System17/11/20257/10/2026
Se ha descubierto una falla de seguridad en itsourcecode Online Voting System 1.0. El elemento afectado es una función desconocida del archivo /ajax.PHP?action=save_user. La manipulación del argumento ID resulta en inyección SQL. La explotación remota del ataque es posible. El exploit ha sido publicado y puede ser…
AnalizadaMedia (5.5)0.41%—Angeljudesuarez Online Voting System17/11/20257/10/2026
Una vulnerabilidad fue identificada en itsourcecode Online Voting System 1.0. El elemento afectado es una función desconocida del archivo /login.php. Tal manipulación del argumento Username lleva a inyección SQL. El ataque puede ser lanzado remotamente. El exploit está disponible públicamente y podría ser usado.
AplazadaMedia (5.5)0.30%—G33kyrash Online-banking-systemAI17/11/20257/10/2026
Una vulnerabilidad fue detectada en el sistema de banca en línea g33kyrash hasta 12dbfa690e5af649fb72d2e5d3674e88d6743455. Esta vulnerabilidad afecta código desconocido del archivo /index.php. La manipulación del argumento Username resulta en inyección SQL. Es posible lanzar el ataque remotamente. El exploit ahora es…
AnalizadaBaja (2.1)0.35%—Oretnom23 Online Magazine Management System17/11/20257/10/2026
Una falla de seguridad ha sido descubierta en SourceCodester Online Magazine Management System 1.0. Esto afecta una parte desconocida del archivo /view_magazine.php. La manipulación del argumento ID resulta en inyección SQL. El ataque puede ser realizado desde remoto. El exploit ha sido publicado al público y puede…
AnalizadaBaja (2.1)0.35%—Oretnom23 Online Magazine Management System17/11/20257/10/2026
Una vulnerabilidad fue identificada en SourceCodester Online Magazine Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /categories.php. La manipulación del argumento c lleva a inyección SQL. El ataque es posible de ser llevado a cabo remotamente. El exploit está…
ModificadaAlta (7.5)0.45%—Oretnom23 Simple Online Book Store System14/11/20255/7/2026
Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db.sql.
ModificadaMedia (5.5)0.39%—Fabian Simple Online Hotel Reservation System14/11/20257/10/2026
Una vulnerabilidad fue detectada en code-projects Simple Online Hotel Reservation System 1.0. Este problema afecta algún procesamiento desconocido del archivo /admin/edit_account.PHP. Realizar una manipulación del argumento admin_id resulta en inyección SQL. El ataque es posible de ser llevado a cabo remotamente. El…
AnalizadaMedia (5.5)0.44%—Fabian Simple Online Hotel Reservation System14/11/20257/10/2026
Una vulnerabilidad de seguridad ha sido detectada en code-projects Simple Online Hotel Reservation System 1.0. Esta vulnerabilidad afecta a código desconocido del archivo /add_query_reserve.PHP. Tal manipulación del argumento room_id lleva a inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido…
AnalizadaBaja (2.1)0.30%—Angeljudesuarez Online Voting System12/11/202517/6/2026
A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AnalizadaAlta (7.8)0.51%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.1)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.48%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.48%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.64%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.1)0.58%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.43%—Projectworlds Online Admission System10/11/20257/10/2026
Una vulnerabilidad fue identificada en projectworlds Online Admission System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /process_login.php. La manipulación del argumento keywords conduce a inyección SQL. El ataque puede ser iniciado remotamente. El exploit está disponible…
AnalizadaMedia (5.5)0.44%—Fabian Online JOB Search Engine10/11/20257/10/2026
Una vulnerabilidad fue detectada en code-projects Online Job Search Engine 1.0. Esto afecta una función desconocida del archivo /login.php. Realizar la manipulación del argumento username/phone resulta en inyección SQL. El ataque es posible de llevar a cabo remotamente. El exploit es ahora público y puede ser usado.
ModificadaBaja (2.1)0.40%—Projectworlds Online Notes Sharing Platform7/11/20257/10/2026
Una vulnerabilidad fue identificada en projectworlds Online Notes Sharing Platform 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /dashboard/userprofile.php. Tal manipulación del argumento image conduce a carga sin restricciones. El ataque puede ser realizado desde remoto. El exploit…
AnalizadaMedia (5.5)0.45%—Angeljudesuarez Online Loan Management System3/11/202517/6/2026
A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the…
AnalizadaMedia (5.5)0.41%—Angeljudesuarez Online Loan Management System3/11/202517/6/2026
A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.41%—Angeljudesuarez Online Loan Management System3/11/202517/6/2026
A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be…
AnalizadaMedia (5.5)0.41%—Angeljudesuarez Online Loan Management System2/11/202517/6/2026
A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.41%—Angeljudesuarez Online Loan Management System2/11/202517/6/2026
A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaBaja (2)0.44%—Fabian Simple Online Hotel Reservation System2/11/202517/6/2026
A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown function of the file /admin/add_account.php. The manipulation of the argument Name results in sql injection. The attack may be performed from remote. The exploit has been released to the public and…
AnalizadaBaja (2)0.43%—Fabian Simple Online Hotel Reservation System2/11/202517/6/2026
A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is…